home / frameworks / pci-dss

// Industry frameworks and attestations

Payment Card Industry Data Security Standard (PCI DSS) v4.0.1

PCI DSS sets 12 requirements for protecting payment card data, published by the PCI Security Standards Council. Version 4.0.1 is the only active version, and all of its requirements have been mandatory since March 31, 2025.

InternationalPCI DSS v4.0.1 (June 2024)

Overview

The Payment Card Industry Data Security Standard (PCI DSS) sets technical and operational requirements for any organization that stores, processes, or transmits payment card account data, or that can affect its security. It is published by the PCI Security Standards Council, which was founded by American Express, Discover, JCB International, Mastercard, and Visa. The current version is v4.0.1. It was published in June 2024 as a limited revision of v4.0 that corrected errors and clarified intent without adding or removing requirements.

PCI DSS is not a law. Card brands build it into their rules, and acquirers, the banks that sign up merchants to accept cards, build it into merchant agreements. The brands and acquirers, not the Council, decide which merchants and service providers must validate compliance and how, whether through a Self-Assessment Questionnaire or a Report on Compliance from a Qualified Security Assessor. Every requirement in v4.0.1, including the 51 that were future-dated, has been mandatory since March 31, 2025.

In Canada, PCI DSS reaches merchants through their acquirer or payment processor, and reaches service providers through contracts with merchants, processors, and banks. Interac Debit is not one of the brands behind the Council and runs under its own rules. Payment service providers may also fall under the Retail Payment Activities Act, supervised by the Bank of Canada, whose risk management and funds safeguarding requirements have applied since September 8, 2025. No Canadian body accredits PCI assessors. The Council qualifies them directly.

Who it applies to in Canada

Any merchant, processor, acquirer, issuer, or service provider that stores, processes, or transmits cardholder data or sensitive authentication data, or that can affect the security of that data.

Canadian merchants accept Visa, Mastercard, American Express, and other brands under acquirer agreements that require PCI DSS compliance. Canadian service providers are asked for PCI DSS attestations by the merchants, processors, and banks they serve.

Controls at a glance

PCI DSS v4.0.1 has 12 principal requirements grouped under 6 goals, each broken into detailed requirements with testing procedures and guidance.

Build and maintain a secure network and systems (Requirements 1 and 2)

  • Requirement 1: install and maintain network security controls
  • Restrict traffic into and out of the cardholder data environment
  • Review network security control rules at least every 6 months
  • Requirement 2: apply secure configurations to all system components
  • Change vendor defaults and remove unneeded services

Protect account data (Requirements 3 and 4)

  • Requirement 3: protect stored account data
  • Keep stored data to a minimum with set retention limits
  • Never store sensitive authentication data after authorization
  • Render stored card numbers unreadable and manage keys
  • Requirement 4: use strong cryptography over open, public networks

Maintain a vulnerability management program (Requirements 5 and 6)

  • Requirement 5: protect all systems and networks from malicious software
  • Anti-malware and anti-phishing controls
  • Requirement 6: develop and maintain secure systems and software
  • Secure software development and timely patching
  • Protect public web applications and payment page scripts

Implement strong access control measures (Requirements 7, 8, and 9)

  • Requirement 7: restrict access by business need to know
  • Requirement 8: identify users and authenticate access
  • Multi-factor authentication for all access into the cardholder data environment
  • Requirement 9: restrict physical access to cardholder data
  • Protect payment terminals from tampering and substitution

Regularly monitor and test networks (Requirements 10 and 11)

  • Requirement 10: log and monitor all access to systems and data
  • Automated log review and retained audit history
  • Requirement 11: test security of systems and networks regularly
  • Internal and ASV external vulnerability scans every 3 months
  • Penetration testing and payment page change detection

Maintain an information security policy (Requirement 12)

  • Requirement 12: support security with organizational policies and programs
  • Targeted risk analyses and annual scope confirmation
  • Security awareness training for staff
  • Manage third-party service providers and shared responsibilities
  • An incident response plan ready to use

Certification and assessment

The entity validates against PCI DSS using either a Report on Compliance prepared by a QSA or a Self-Assessment Questionnaire, then signs an Attestation of Compliance. The acquirer or card brand decides which method applies. Where required, quarterly external scans by an ASV are submitted as well.

Dates to know

2022-03
PCI DSS v4.0 published
2024-03-31
PCI DSS v3.2.1 retired
2024-06-11
PCI DSS v4.0.1 published as a limited revision
2024-12-31
PCI DSS v4.0 retired, leaving v4.0.1 as the only active version
2025-01-30
Revised SAQ A published, replacing Requirements 6.4.3, 11.6.1, and 12.3.1 with a new eligibility criterion
2025-03-31
Future-dated PCI DSS v4.x requirements become mandatory and the revised SAQ A takes effect
2025-09-08
Retail Payment Activities Act risk management and safeguarding requirements apply to Canadian payment service providers
2026-07-20
PCI SSC request for comments on v4.0.1, opened June 3, 2026, closes to inform the next version

In this hub

Resources

Official texts and free tools for PCI DSS. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Just Published: PCI DSS v4.0.1, PCI Security Standards Council
  2. PCI Data Security Standard (PCI DSS), PCI Security Standards Council
  3. Merchant Resources, PCI Security Standards Council
  4. Important Updates Announced for Merchants Validating to Self-Assessment Questionnaire A, PCI Security Standards Council
  5. Retail payments supervision, Bank of Canada